MikroTik , the network equipment manufacturer, has provided some advice on how customers can protect routers that were affected by the massive Mēris DDoS botnet over the summer.
See also: Meris botnet attacks KrebsOnSecurity website

“From what we have seen, these attacks are using the same routers that were compromised in 2018, when MikroTik RouterOS had a vulnerability that was quickly patched,” a MikroTik spokesperson told BleepingComputer.
However, the company warned that fixing the vulnerability does not necessarily mean that all routers are secure. If someone obtained the users' passwords in 2018, the update does not help.
Users should change their password, check their firewall to make sure it does not allow remote access to third parties, and check for scripts that they did not create themselves.
Mēris botnet
The Mēris botnet was responsible for two massive DdoS attacks that took place not long ago.
See also: New Zealand: Post Office and banks affected by DDoS attack
The first attack, which Cloudflare mitigated in August, reached 17.2 million requests per second (RPS). The second exceeded all limits, reaching 21.8 million RPS, affecting Yandex serversearlier this month.
According to researchers at Qrator Labs, the Mēris botnet, which originated from the Mirai malware code, now controls approximately 250,000 devices, most of which are MikroTik network gateways and routers.

How to protect MikroTik routers?
MikroTik recommends that customers choose strong passwords that can protect devices from brute-force attacks. Additionally, devices should be up-to-date to prevent exploits of vulnerabilities used by the Mēris botnet.
See also: DDoS attacks: Best practices for prevention/countermeasures
The company recommended to users to follow the steps below to stay safe:
- Update MikroTik devices (routers etc) regularly.
- Do not let anyone have access to your device via the internet. If you need remote access, open only a secure VPN service.
- Use a strong password. If you already have a strong password, but you think your device is at risk, change it!
- Do not consider your local network trustworthy. Malware may attempt to connect to your MikroTik router if you have a weak password or if you are not using a password.
- Check the RouterOS configuration for unknown settings.
The settings that the malicious software Mēris may set during the reconfiguration of compromised MikroTik routers include:
- System -> Scheduler rules that execute a Fetch script. Remove them.
- IP -> Socks proxy. If you are not using this feature or do not know what it does, you should disable it.
- L2TP client named “lvpn” or an L2TP client you do not recognize.
- Input firewall rule that allows access to port 5678.
MikroTik said that it tried to contact all RouterOS users to inform them about the security issue, but many of them did not respond and do not check their devices. The company said it is trying to find other solutions.
"As far as we are aware at this time, there are no new vulnerabilities in these devices," the company said.
Source: Bleeping Computer
